cardkhata

Privacy Policy

What we collect, and why.

cardkhata reads the credit-card statements you choose to forward, and nothing else. This page lists exactly what the service stores, what it is used for, and what never touches our servers.

Last updated: 12 September 2026

Who we are

cardkhata (cardkhata.in) is a credit-card statement analyzer for the Indian market, operated from India by the site owner (developer site: ankitbhardwaj.in). For anything in this policy, write to support@cardkhata.in.

What we collect

  • Account details — the email address you sign in with, and your mobile number.
  • Optional profile secrets — your date of birth, your first name as printed on the card, and your mobile number, if you choose to save them. They are used for one purpose only: deriving the passwords that open your statement PDFs. They are encrypted at rest and are never displayed back to you or anyone else.
  • Statements — the credit-card statement PDFs you forward to your cardkhata address, and the transactions, EMIs, and fees parsed from them.

That is the full list. cardkhata never asks for your bank login, net-banking password, OTPs, or full card number, and has no way to receive them.

What we use it for

Your data is used to parse your statements and show you your own spending analytics — categorised transactions, EMI schedules, fees, and month-to-month comparisons. Nothing else is built on it.

  • We do not sell your data, and we do not share it with advertisers or data brokers.
  • It is shared only with the payment gateway (to bill your subscription) and with the infrastructure providers that run the service (such as AWS, where statements are stored), strictly as needed to operate cardkhata.

Payments

Subscription payments are processed by third-party payment gateways (Razorpay and/or Cashfree). Your card or UPI details are entered on the gateway’s own checkout and go directly to the gateway — they never touch cardkhata’s servers. PCI compliance for payment data is handled by the gateway. The plan and price are always shown to you before you pay.

How it's protected

  • Profile secrets used for PDF passwords are encrypted at rest.
  • Forwarded statement PDFs are stored encrypted in cloud storage.
  • Access is limited to what the service needs to parse and display your statements.

No system is perfectly secure, but the design principle throughout is to hold as little as possible and to encrypt what must be held.

Your choices

  • You choose what to forward — cardkhata only ever sees statements you send it.
  • Saved profile secrets are optional, and you can remove them from your Profile.
  • You can cancel your subscription from your Profile page at any time — access continues until the paid period ends, with no separate account deactivation.
  • For a copy of your data or a deletion request, email support@cardkhata.in with the subject line “Privacy” from your account email.

Changes to this policy

If this policy changes in a way that matters, we will update this page and its “Last updated” date, and flag significant changes in the product. Continued use of cardkhata after a change means you accept the updated policy.

Contact

Questions about privacy, or about anything on this page: support@cardkhata.in. See also our Terms & Conditions and Refund & Cancellation Policy.